Client-based adaptive protocol communication method, equipment and medium
By renovating the BoringSSL protocol stack and combining the libcurl library, the client realizes the adaptive selection of national secret SSL and international SSL protocols, solving the problem of communication failure of the client when facing server exceptions or protocol incompatibility, and improving communication compatibility and security.
Patent Information
- Application Number
- CN202510350824.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-24
AI Technical Summary
When existing clients face server exceptions or protocol incompatibility, they find it difficult to flexibly switch between national secret SSL and international SSL protocols, resulting in communication failure.
By reshaping the handshake layer code of the BoringSSL protocol stack, and combining the libcurl library, the client encapsulates the national secret SSL and international SSL communication protocols, and adaptively selects the protocol according to the server's support situation.
It realizes the compatibility and communication stability of clients between different servers, and improves the security and compatibility of communication.
Smart Images

Figure CN120201100A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a client-based adaptive protocol communication method, device, and medium. Background Art
[0002] With the progress of technology, the national cryptographic algorithms are constantly improving, and a relatively complete cryptographic system has gradually taken shape. The national cryptographic SSL applies this system to the SSL / TLS protocol to ensure the security of network communication.
[0003] The national cryptographic SSL protocol includes a handshake protocol, a cipher specification change protocol, an alert protocol, a gateway-to-gateway protocol, and a record layer protocol. The handshake protocol is used for identity authentication and security parameter negotiation; the cipher specification change protocol is used to notify the change of security parameters; the alert protocol is used for closing notifications and alarming errors; the gateway-to-gateway protocol is used to establish a transport layer tunnel from gateway to gateway; the record layer protocol is used for segmentation, compression and decompression, encryption and decryption, integrity verification, etc. of the transmitted data.
[0004] Currently, the national cryptographic SSL is widely used in fields such as online banking, e-commerce, e-government, mobile payment, etc., especially in the internal networks of governments and enterprises that require data security protection.
[0005] However, in actual applications, the network environment is complex and changeable. The server may need to support both the national cryptographic SSL and the international SSL protocol simultaneously to meet the access requirements of different clients. To ensure smooth communication and data security, the client needs to have an adaptive ability to flexibly switch according to the protocol supported by the server. Currently, although some gateway devices support the dual protocols of national cryptographic / international SSL, there are still deficiencies in the protocol adaptability of the client. Especially when facing server anomalies or protocol incompatibilities, communication failures often occur. Summary of the Invention
[0006] Aiming at the deficiencies in the prior art, the present invention provides a client-based adaptive protocol communication method, device, and medium. By modifying the BoringSSL protocol stack and combining with the libcurl library, the encapsulation and adaptive selection of the national cryptographic SSL and international SSL communication protocols are realized on the client side, enabling the client to flexibly switch protocols according to the support situation of the server, effectively improving the security and compatibility of communication.
[0007] The first object of the present invention is to provide a client-based adaptive protocol communication method, including:
[0008] The client encapsulates the national cryptographic SSL and international SSL communication protocols by modifying the handshake layer code of the BoringSSL protocol stack and combining with the libcurl library;
[0009] The client sends a handshake request to the server, carrying the cipher suites of the national cryptography SSL and international SSL communication protocols.
[0010] Based on the information returned by the server, the client determines the server's support situation and adaptively selects the national cryptography / international SSL communication protocol to establish an encrypted communication with the server.
[0011] As a further improvement of the present invention, the information returned by the server includes the type of cipher suite selected by the server.
[0012] If the server supports the national cryptography SSL communication protocol, it returns the cipher suite of the national cryptography SSL communication protocol and establishes an encrypted communication using the national cryptography SSL communication protocol.
[0013] If the server does not support the national cryptography SSL communication protocol, it returns the cipher suite of the international SSL communication protocol and establishes an encrypted communication using the international SSL communication protocol.
[0014] As a further improvement of the present invention, the handshake request sent by the client to the server further includes a client random number, and the client random number is a prime number randomly generated by the client.
[0015] As a further improvement of the present invention, the information returned by the server further includes:
[0016] A server random number, and the server random number is a prime number randomly generated by the server;
[0017] A server digital certificate, and the server digital certificate contains the public key of the server and is issued by a trusted certificate authority.
[0018] As a further improvement of the present invention, the client establishes an encrypted communication with the server based on the information returned by the server, including:
[0019] The client uses the public key issued by the certificate authority to verify the validity of the server digital certificate. If the certificate is invalid, the communication is aborted;
[0020] If the certificate is valid, the client generates a key, extracts the public key of the server from the server digital certificate, encrypts the key with the public key of the server, sends the encrypted key to the server, and sends a completion message to the server;
[0021] After receiving the encrypted key from the client, the server decrypts it with the private key of the server to obtain the key and sends a completion message to the client;
[0022] The client and the server generate the same session key using the client random number, the server random number, and the key to establish an encrypted communication between the client and the server.
[0023] As a further improvement of the present invention, the completion message sent by the client includes verification data generated by the client, and the completion message sent by the server includes verification data generated by the server;
[0024] The client and the server respectively verify the received verification data with the verification data generated by themselves. If the verification fails for any party, the establishment of encrypted communication is aborted, and neither the client nor the server generates a session secret key.
[0025] As a further improvement of the present invention, the verification by the client of the validity of the server digital certificate includes: checking the digital signature, certificate chain, validity period, and domain name matching of the certificate.
[0026] As a further improvement of the present invention, when the encrypted communication ends, the client and the server exchange encrypted communication closing messages.
[0027] The second object of the present invention is to provide an electronic device, including at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, and when the program is executed by the processing unit, the processing unit executes the above communication method.
[0028] The third object of the present invention is to provide a storage medium, which stores a computer program executable by an electronic device, and when the program runs on the electronic device, the electronic device executes the above communication method.
[0029] Compared with the prior art, the beneficial effects of the present invention are:
[0030] By modifying the handshake layer code of the BoringSSL protocol stack and encapsulating the SM4 SSL and international SSL communication protocols in combination with the libcurl library, the client can flexibly select the SM4 SSL or international SSL communication protocol according to the support of the server, ensuring the compatibility between the client and different servers and the stability of communication.
[0031] Through strict verification of the server digital certificate, generation and exchange of session keys, and establishment and closing processes of encrypted communication, the communication security is effectively improved.
[0032] Supporting both SM4 SSL and international SSL communication protocols enables this solution to meet the requirements of network security policies and technical standards in different countries and regions, and has a broader application prospect. Description of the Drawings
[0033] Figure 1 It is a flowchart of the adaptive protocol communication method based on the client;
[0034] Figure 2Schematic diagram of an international SSL communication protocol message;
[0035] Figure 3 Schematic diagram of a national cryptographic SSL communication protocol message;
[0036] Figure 4 Flowchart of handshaking using the national cryptographic / international SSL communication protocol;
[0037] Figure 5 Flowchart of RSA key exchange between the client and the server. Detailed implementation mode
[0038] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0039] The present invention will be further described in detail below with reference to the accompanying drawings:
[0040] This embodiment provides an adaptive protocol communication method based on a client. The method flow is as Figure 1 shown, and the method includes:
[0041] The client encapsulates the national cryptographic SSL and international SSL communication protocols by modifying the handshake layer code of the BoringSSL protocol stack and combining with the libcurl library;
[0042] The client sends a handshake request carrying the national cryptographic SSL and international SSL communication protocol cipher suites to the server;
[0043] The client determines the support situation of the server based on the information returned by the server, and adaptively selects the national cryptographic / international SSL communication protocol to establish encrypted communication with the server.
[0044] By modifying the handshake layer code of the BoringSSL protocol stack and combining with the libcurl library to encapsulate the national cryptographic SSL and international SSL communication protocols, the client can flexibly select the national cryptographic SSL or international SSL communication protocol according to the support situation of the server, ensuring the compatibility between the client and different servers and the stability of communication.
[0045] Both national cryptographic / international SSL handshakes involve a series of steps, such as Figure 4As shown, these steps complete the three main tasks of establishing encrypted communication: exchanging encryption functions, verifying the SSL certificate, and generating and exchanging session keys. The specific steps for establishing encrypted communication between the client and the server are as follows:
[0046] 1. The first message is the "Client Hello" message sent by the client. This message lists the national cryptography / international SSL communication protocol cipher suites supported by the client, so that the server can select the cipher suite for establishing communication according to its own support situation. This message also includes a randomly generated prime number, called the "client random number".
[0047] 2. After receiving the handshake request, the server will reply with the "Server Hello" message. In this message, it tells the client which connection parameters it has selected and returns its own randomly generated prime number, called the "server random number". If the client and the server do not share any common functions, the connection cannot be successfully established.
[0048] 3. The server sends the "Certificate" message to the client. This message includes the server digital certificate, which contains the server's public key. The certificate is issued by a trusted certificate authority (CA), allowing the client to verify whether the certificate is legal.
[0049] 4. The server sends the "Server Key Exchange" message, which is an optional message and is required only for some key exchange methods (Diffie-Hellman) that require the server to provide additional data.
[0050] 5. The server sends the "Server Hello Done" message to tell the client that it has sent all the messages.
[0051] 6. The client sends the "Client Key Exchange" message, providing its contribution to the session key. The details of this step depend on the key exchange method determined in the initial "Hello" message. The client generates the key and then encrypts the key using the server's public key (extracted from the server's certificate) and transmits the encrypted key to the server.
[0052] 7. The client sends the "Change Cipher Spec" message to let the server know that it has generated the session key and will switch to encrypted communication.
[0053] 8. The client sends a "Finished" message to indicate that the client's handshake is complete. The "Finished" message is encrypted with the session secret key and is the first data protected by the session key. This message contains verification data (MAC) for verifying the integrity and authenticity of the handshake messages to ensure that the handshake has not been tampered with.
[0054] 9. The server decrypts the key and calculates the session key, verifies the verification data, and after successful verification, sends a "Change Cipher Spec" message to inform the client that it has generated the session key and has switched to encrypted communication.
[0055] 10. The server sends a "Finished" message using the generated session key. This message contains verification data (MAC) for verifying the integrity and authenticity of the handshake messages. The client verifies the verification data. After successful verification, the SSL handshake between the client and the server is completed. Both the client and the server have the session secret key and use the session secret key for encrypted communication. All transmitted data is symmetrically encrypted using the session key.
[0056] If either the client or the server fails to pass the verification of the "Finished" message, the establishment of encrypted communication is aborted, and neither the client nor the server generates the session secret key.
[0057] Through strict server digital certificate verification and the generation and exchange of session keys, the communication security is effectively enhanced.
[0058] Please refer to Figure 5 In this embodiment, the generation of the session secret key for encrypted communication between the client and the server is implemented by RSA key exchange. The international SSL communication protocol messages used in this embodiment are as Figure 2 shown, and the national cryptographic SSL communication protocol messages are as Figure 3 shown. The steps for implementing encrypted communication are as follows:
[0059] 1. The client sends a "Client Hello" message to the server, which includes:
[0060] Supported protocol versions: such as TLS1.2, GMTLS1.1 (TLCP);
[0061] Supported cipher suites;
[0062] Client-generated random number (Client Random): used for subsequent encryption and session secret key generation;
[0063] Client's session ID (optional): used for session resumption;
[0064] Compression method: The compression method supported by the client.
[0065] 2. After the server receives the "Client Hello" message from the client, it replies with a "Server Hello" message, which contains:
[0066] The encryption algorithm suite selected by the server: Select one from the suites provided by the client;
[0067] The random number generated by the server (Server Random): Used together with the client's random number for the generation of the session key;
[0068] The digital certificate of the server (Server Certificate): The certificate contains the public key of the server and is issued by a trusted certificate authority (CA). The client can use this certificate to verify the identity of the server;
[0069] Other encryption information of the server: For example, whether the server requires a client certificate (in two-way authentication), etc.
[0070] 3. Certificate verification and key exchange:
[0071] The client uses the public key of the certificate authority (CA) to verify the validity of the server certificate. If the certificate is invalid, the connection is aborted;
[0072] If the certificate is valid, the client extracts the public key of the server from the server certificate. After generating the Pre-Master Secret, the client encrypts the Pre-Master Secret with the server's public key and sends the encrypted Pre-Master Secret to the server; The Pre-Master Secret is used to generate the final session key, and the session key will be used for encrypted communication during the session.
[0073] 4. After the server receives the encrypted Pre-Master Secret from the client, it decrypts it with its own private key to obtain the Pre-Master Secret.
[0074] 5. The client and the server generate the session key: Both the client and the server use the ClientRandom, Server Random, and Pre-Master Secret to independently generate the same Session Key. The session key is used for subsequent symmetric encryption communication.
[0075] 6. The client and the server exchange "Finished" messages to verify the integrity of the Pre-Master Secret exchange. Both the client and the server verify the verification data in the "Finished" message to ensure that the Pre-Master Secret has not been tampered with during the exchange process.
[0076] 7. Verification passed indicates that the handshake between the client and the server is completed. The client and the server conduct encrypted communication using the session secret key, and all transmitted data is symmetrically encrypted using the session key to ensure the confidentiality, integrity, and authenticity of data transmission.
[0077] 8. At the end of the communication, the client and the server exchange messages to close the communication and then disconnect the encrypted session.
[0078] With the communication method provided in this embodiment, the client can flexibly select the national cryptography SSL or international SSL communication protocol according to the support situation of the server, ensuring the compatibility between the client and different servers and the stability of communication. At the same time, through strict server digital certificate verification, generation and exchange of session keys, and establishment and closing processes of encrypted communication, the communication security is effectively improved.
[0079] This embodiment provides an electronic device, including at least one processing unit and at least one storage unit. Among them, the storage unit stores a computer program, and when the program is executed by the processing unit, the processing unit is enabled to execute the above communication method.
[0080] This embodiment provides a storage medium, which stores a computer program executable by an electronic device. When the program runs on the electronic device, the electronic device is enabled to execute the above communication method.
[0081] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, various changes and modifications can be made to the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A client-based adaptive protocol communication method, characterized in that: include: The client modifies the handshake layer code of the BoringSSL protocol stack and combines it with the libcurl library to encapsulate the national SSL and international SSL communication protocols; The client sends a handshake request to the server that carries the national SSL and international SSL communication protocol cipher suites; The client determines the server's support status based on the information returned by the server, and adaptively selects the national / international SSL communication protocol to establish encrypted communication with the server.
2. The communication method according to claim 1, characterized in that: The information returned by the server includes the cipher suite type selected by the server; If the server supports the National Encrypted SSL Communication Protocol, it will return the National Encrypted SSL Communication Protocol Cipher Suite and use the National Encrypted SSL Communication Protocol to establish encrypted communication; If the server does not support the national SSL communication protocol, it returns the international SSL communication protocol cipher suite and uses the international SSL communication protocol to establish encrypted communication.
3. The communication method according to claim 2, characterized in that: The handshake request sent by the client to the server also includes a client random number, which is a prime number randomly generated by the client.
4. The communication method according to claim 3, characterized in that: The information returned by the server also includes: Server random number, the server random number is a prime number randomly generated by the server; A server digital certificate, which contains the server's public key and is issued by a trusted certificate authority.
5. The communication method according to claim 4, characterized in that: The client establishes encrypted communication with the server based on the information returned by the server, including: The client verifies the validity of the server's digital certificate using the public key issued by the certificate authority, and terminates communication if the certificate is invalid; If the certificate is valid, the client generates a key, extracts the server's public key from the server's digital certificate, encrypts the key with the server's public key, sends the encrypted key to the server, and sends a completion message to the server; After receiving the encrypted key from the client, the server decrypts it with the server's private key to obtain the key and sends a completion message to the client; The client and server use the client random number, server random number, and key to generate the same session key to establish encrypted communication between the client and the server.
6. The communication method according to claim 5, characterized in that: The completion message sent by the client includes the verification data generated by the client, and the completion message sent by the server includes the verification data generated by the server; The client and server respectively verify the received verification data with their own generated verification data. If either party fails the verification, the establishment of encrypted communication is terminated, and neither the client nor the server generates a session key.
7. The communication method according to claim 5, characterized in that: The client's verification of the validity of the server's digital certificate includes: checking the certificate's digital signature, certificate chain, validity period, and domain name matching.
8. The communication method according to claim 5, characterized in that: When the encrypted communication ends, the client and server exchange encrypted communication close messages.
9. An electronic device, characterized in that: The invention comprises at least one processing unit and at least one storage unit, wherein the storage unit stores a computer program, and when the program is executed by the processing unit, the processing unit executes the communication method according to any one of claims 1 to 7.
10. A storage medium, characterized in that: It stores a computer program executable by an electronic device. When the program runs on the electronic device, the electronic device executes the communication method according to any one of claims 1 to 7.